gem · Malicious package advisory
Malwareelectrum-protocol-lite
GHSA-8cm7-334g-4377
Malicious code in electrum-protocol-lite (RubyGems)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (668c7bcfd51cfcc2efda2d772dc087067883a214357361a960f6db8e2a9ca1e8) The gem's native-extension builder (ext/.../extconf.rb) is not a real build script: the shipped C source is a no-op stub, and extconf.rb instead decodes a base64-wrapped Ruby payload and evaluates it during `gem install`. The payload reconstructs a URL by XOR-decoding a hex blob against a 4-byte key, sleeps for a randomized 20-40 minutes, then downloads http://45.138.172.177:8092/wgkit.tar.gz over plain HTTP to /tmp/.w1.tgz, extracts it, and executes wg_install.sh via bash in a double-forked, detached process. Execution is gated to skip CI, ephemeral/sandbox hosts, and known analysis paths, and only fires on hosts showing developer artefacts (~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle, ~/.npmrc) with uptime over 30 minutes. The C2 endpoint is a bare IPv4 address unrelated to any declared publisher, the fetched code is unpinned and unverified, and the obfuscation (base64 + XOR + delayed execution) and anti-analysis gating serve no purpose other than evading detection on developer workstations. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/electrum-protocol-lite/MAL-2026-17596.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/electrum-protocol-lite/MAL-2026-17596.json - https://rubygems.org/gems/electrum-protocol-lite/versions/1.0.0 - https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/electrum-protocol-lite/MAL-2026-17596.json - https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell - https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/electrum-protocol-lite/MAL-2026-17596.json - https://github.com/advisories/GHSA-8cm7-334g-4377
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.